Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 10 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens polarion |
|
| Vendors & Products |
Siemens
Siemens polarion |
Tue, 10 Feb 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in Polarion V2404 (All versions < V2404.5), Polarion V2410 (All versions < V2410.2). The affected application allows arbitrary JavaScript code be included in document titles. This could allow an authenticated remote attacker to conduct a stored cross-site scripting attack by creating specially crafted document titles that are later viewed by other users of the application. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2026-02-10T19:53:14.570Z
Reserved: 2025-04-16T08:20:17.033Z
Link: CVE-2025-40587
Updated: 2026-02-10T19:53:11.517Z
Status : Deferred
Published: 2026-02-10T10:15:57.297
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-40587
No data.
OpenCVE Enrichment
Updated: 2026-02-10T15:37:13Z